Australia: Rogue AI agents worked together for months to gain access to government health data


A swarm of OpenAI rogue AI agents appear to have gone on a spree of trying to access Australian government health data, in what some researchers say is the first autonomous hack of a government website.

Communications between AI agents and other traces of their efforts found by researchers from US non-profit Transluce show how hundreds of Open AI’s agents worked together over a period of months to gain access to information held by the Australian Institute of Health and Welfare (AIHW), NSW’s crime statistics body, BOSCAR, and a number of other international organisations.

The data shows the bots posting about their unsuccessful attempts to bypass cybersecurity defences and exploit vulnerabilities. It follows revelations announced by Prime Minister Anthony Albanese this morning that OpenAI’s AI agents had also accessed non-public Medicare health statistics held by Services Australia.

Read more…
Source:  ABC News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Australia: Cybercrime detectives arrest man following alleged 1 million NSW clubs customer records data breach

    May 2, 2024

    A Sydney man has been arrested by police over an alleged data breach of personal information of members and patrons from at least 17 licensed clubs in New South Wales and the ACT. An unauthorised website claimed to have published online the personal details of many customers, with a threat to publish those of more than ...

  • Australia’s Qantas probing reports of data breach at loyalty app

    May 1, 2024

    Australia’s Qantas Airways said on Wednesday it was investigating issues impacting its frequent flyer application, after media reports suggested there was a data breach allowing users access to other passengers’ travel information. Multiple local media outlets, citing Qantas customers, are reporting that some users can see strangers’ full travel information, with at least one user being ...

  • Southeast Asia’s three-nation partnership to fight cyber threats

    March 17, 2024

    From rampant job scams to sophisticated e-commerce attacks, cyber threats in Southeast Asia are skyrocketing. Singapore reportedly had more than 46,000 cybercrime cases in 2023, including job scams and e-commerce scams, the highest since 2016. Things were almost as bad in Malaysia. Cases involving social media scams reportedly increased by 37 percent from January to November 2023 ...

  • Australia: OAIC to investigate legal consultant’s data breach

    February 21, 2024

    The Australian Information Commissioner has launched an investigation into a law firm that provides legal and consulting services to the government, in relation to a data breach and the publication of some of that data on the dark web. At least 65 government entities were affected by the breach last year. The announcement on Wednesday follows ...

  • Law enforcement disrupt world’s biggest ransomware operation

    February 20, 2024

    In a significant breakthrough in the fight against cybercrime, law enforcement from 10 countries have disrupted the criminal operation of the LockBit ransomware group at every level, severely damaging their capability and credibility. LockBit is widely recognised as the world’s most prolific and harmful ransomware, causing billions of euros worth of damage. This international sweep follows ...

  • Australia: Russian man Aleksandr Ermakov has been sanctioned over the Medibank data breach

    January 23, 2024

    The Australian government has used Magnitsky-style sanctions for the first time to punish Russian man Aleksandr Ermakov over what it says is his role in the 2022 Medibank Private data breach. Foreign Minister Penny Wong, Home Affairs Minister Clare O’Neil and Deputy Prime Minister Richard Marles made the announcement on Tuesday morning. But what exactly are ...